Privacy Policy

Last updated: 2026-10-03 Version: 2.4 Status: Publication notice Effective: On publication of this edition

This notice explains the processing and choices applicable to the features you use. It applies when this edition is published. Descriptions of upcoming features do not mean they are already enabled. Contract changes have their own notice and application dates; this notice is not a request for contractual acceptance or optional cookie consent.

This notice explains personal-data processing by Supa Labs OÜ, registry code 17399414, Oru tn 2, Tallinn 10127, Estonia ("Swaps"), across our websites, dashboard, mobile and mini apps, API, MCP tools and communications. Privacy contact: legal@swaps.app.

1. Who is responsible

Swaps is a controller when it determines why and how data is used for account administration, Service operation, billing, security, fraud prevention, support and its own legal obligations.

Where Swaps processes personal data for a business customer's purposes and on its documented instructions, such as relevant recipient-record or invoice workflows, it acts as a processor for that processing. The applicable data processing agreement records the scope and obligations. Legal roles depend on the actual activities, not merely on an agreement's title or whether a template has been signed. Contact the relevant employer, merchant or business customer about its processing; we can help direct your request.

A payment, identity, blockchain or other provider may separately act as a controller for verification, execution, screening, record keeping and its own obligations. Its notice applies to that processing. A provider is not our processor simply because our interface connects to it. A merchant, employer, agent host or integration operator can also have its own responsibilities.

2. Data, sources and purposes

The data processed depends on the features you use. We receive data from you, authorised account users, merchants and payers, employers and recipients, your device, providers, public blockchains and screening sources.

Data categoryExamplesMain use
Account and business dataEmail, name, language, account type, organisation details, membership, roles, permissions, verification identifiers and statusAccess, account administration, eligibility, communication
Authentication and securityAuth tokens, password hashes where used, OAuth identifiers, passkey public keys and credential metadata, API-key hashes, scopes, expiry, access logs, IP and device/browser informationSign-in, request authentication, fraud prevention, incident investigation
Contract acceptance and authorityActing user and personal or business-account identifiers, verified login-session identifier (UUID), challenge and receipt identifiers, server timestamps, acceptance method, and linked release, document versions and content hashesRecording which terms were accepted, by whom and for which person or business; checking authority and handling related disputes
Transactions and wallet contextWallet and contract addresses, network and asset, amounts, fees, quotes, provider references, transaction hashes, funding and settlement events, beneficiary and return instructionsPreparing and routing instructions, displaying status, reconciliation, support
Merchant and invoice informationMerchant identity, invoice descriptions and line items, customer or payer contact details, payment requests, subscription schedule and invoice historyIssuing invoices and links, reminders, payment administration
Payroll and supplier paymentsNames, emails, relationship or payment descriptions, amounts, bank or wallet destinations, supporting instructions and statusPreparing and delivering payment instructions, recipient onboarding, reconciliation
Bank details and complianceAccount-holder details, virtual-account or bank instructions, provider customer IDs, KYC/KYB outcomes, requirement requests, correspondence and submitted attachmentsProvider onboarding, eligibility, responding to compliance requests, investigation
Address Check and address intelligenceQueries, addresses, transaction references, reports, saved lists, monitoring requests and risk signalsProducing and retaining requested reports, monitoring, abuse controls
Purchases and billingPurchased plan or credits, invoices, payment processor references, billing country and limited payment-method details supplied by the processorBilling, refunds, accounting; payment-card entry is handled by the payment processor
Support and communicationsMessages, attachments, complaint history, delivery and bounce status, response and unsubscribe recordsSupport, service notices, delivery management and permitted marketing
Operational telemetryServer request IDs, errors, latency, financial audit events, technical diagnostics and security signalsOperating, debugging and securing the Service, investigating failed requests
Optional analytics and marketingPage and interaction events, online identifiers and campaign information when enabledMeasuring usage or campaigns and providing the optional features you choose

An account sign-in passkey and a wallet signing passkey have different uses. We process public credential and transaction metadata; do not send us private keys, seed phrases or passkey secrets. A device's biometric check is handled by the device or credential provider, rather than a biometric template being sent to Swaps for that check.

Where the versioned acceptance process is enabled, the server associates the acceptance with the authenticated user, verified session and displayed personal or business account. Document hashes link the record to the published text; a client-supplied checkbox, email opening or API key does not establish acceptance. The acceptance record does not store a raw authentication token, email address, IP address or user-agent string. Separate account, security and operational records can contain the data described above. Contract acceptance is distinct from consent to optional processing.

Verification may start on a provider-hosted page. We can nevertheless receive provider identifiers, outcomes, requests, correspondence and documents you submit through our compliance or support channels. Do not assume documents sent to Swaps bypass our systems. Use the designated verification channel and avoid unnecessary sensitive information. If a document includes special-category data, processing requires the additional legal conditions applicable to that data; ordinary contract performance alone is not sufficient.

Payment pages and shared reports can expose information to people who have their link. Public blockchain addresses and transactions can be personal data even if no name is shown. Avoid putting private information in public descriptions or on-chain fields.

3. Why processing is lawful

For EEA and UK processing, we use the following bases where their conditions are met:

PurposeBasis
Providing a feature you request, administering your account or purchase, and handling related supportPerformance of a contract with you, or steps you request before a contract
Operating business accounts and communicating with representatives, workers, beneficiaries or payers who are not parties to our contractLegitimate interests in delivering and administering the requested service, subject to their rights; the customer's separate basis applies to its disclosures
Recording contract acceptance and the representative's authorityPerformance of the contract with the individual where necessary; otherwise legitimate interests in documenting the business relationship, verifying authority and establishing or defending claims, subject to the person's rights
Security, fraud prevention, troubleshooting, limited operational measurement, defending claims and service integrityLegitimate interests in protecting users and operating a reliable service, after considering impact and necessity
Accounting, responding to binding legal demands and obligations that actually apply to SwapsCompliance with the relevant legal obligation
Optional analytics, marketing storage and marketing communications where consent is requiredYour consent, which can be withdrawn
Other marketing permitted by lawConsent or the applicable legitimate-interest basis and communication rules, with an opt-out

We do not treat every provider compliance request as a legal obligation imposed on Swaps. Depending on the circumstances, facilitating such a request may be needed for the requested service or for a legitimate interest, while the provider relies on its own basis.

Where we rely on legitimate interests, you may object. We assess the objection and stop unless the law permits continued processing; direct-marketing objections are honoured. Where data is necessary for a contract or legal requirement, declining to provide it may prevent the relevant feature. Optional choices are not a condition of essential access.

4. Retention

We retain personal data only for as long as needed for the relevant purpose and applicable obligations. There is no single retention period for all records.

RecordRetention criterion
Account and profileWhile needed to operate the account, then deletion or anonymisation unless a specific continuing purpose applies
Payment, invoice, payroll and reconciliation recordsCompletion and dispute handling, followed by the period required for applicable accounting or legal records; only necessary fields are retained
Verification and compliance correspondenceThe request and eligibility purpose, plus any specific legal or documented dispute/investigation need; provider retention can differ
Authentication, security and error recordsThe time needed to detect, investigate and resolve misuse or defects, proportionate to the record's sensitivity and incident
Support and complaintsResolution, follow-up and any applicable limitation or legal record period
Contract acceptance and authority evidenceWhile necessary to establish the applicable agreement and authority, administer the relationship and address claims within applicable limitation periods; longer only for a specific legal obligation or relevant legal hold
Consent and preference evidenceWhile needed to honour and demonstrate the choice, and to address a related dispute
Optional analyticsThe relevant consent, configuration and measurement purpose, with deletion or aggregation when no longer needed
BackupsThe applicable backup cycle and recovery need; restricted copies are not used to resume ordinary processing after deletion

An account-deletion request does not erase public blockchain records or data that another controller must retain. Where we retain particular data after closure, we restrict its use to the continuing purpose. A legal hold applies to relevant records, not an automatic indefinite hold on an entire account. Ask legal@swaps.app for the period or criteria applicable to your records.

Account closure does not automatically erase necessary contract evidence. Retention and erasure are assessed for the relevant person, business and purpose; the presence of a contract record does not justify keeping all associated personal data indefinitely. Uncompleted acceptance challenges are retained only as needed for their limited security and evidence purpose. Challenge expiry prevents a new acceptance through that challenge but does not itself promise automatic deletion. Where a business record must remain, unnecessary actor or session identifiers can be removed without rewriting the terms that the business accepted.

5. How we use and disclose data

We use data for the purposes above, not simply for any purpose an integration permits. Transaction details may be sent to a chosen provider, network, merchant or recipient as needed for the requested instruction. Some payment and compliance rules require information about the sender, recipient or source of funds. We may need to request additional information or stop a route if it cannot be provided lawfully.

Support and compliance processes can use email and document storage as well as the application database. AI-assisted support, report explanations and output-quality checks may process the relevant prompt, content or draft. See the AI Disclosure. Avoid unnecessary personal or confidential data in prompts.

6. Recipients

The following categories may receive data relevant to their function. Names describe integrations, not a statement that every recipient receives every user's data or acts in the same legal role.

Recipient categoryExamples and purpose
Hosting, database, authentication and network infrastructureSupabase, Vercel and Cloudflare for hosting, storage, authentication, delivery and security
Communications and administrationResend and Google Workspace for email delivery, support and compliance correspondence and documents
Diagnostics and optional measurementSentry for error diagnostics; Google Analytics, tag infrastructure and Vercel Analytics/Speed Insights for optional measurement when enabled
Billing and selected financial providersStripe for relevant purchases; the applicable Bridge entity or chosen ramp provider for onboarding, payment and payout services
Blockchain and cross-network infrastructureRelay, network/RPC services and block explorers to quote, submit, relay or examine transactions
Risk and identity servicesScreening, blockchain-intelligence and provider identity-verification services used for the selected workflow
AI servicesAI infrastructure, including OpenAI in relevant assistance and output-checking workflows, to process the content needed for that feature
Transaction participants and customer systemsYour merchant, employer, beneficiary, authorised business users, webhook endpoint or integration as required for the instruction
Professional advisers and authoritiesWhere necessary for advice, a legal claim or a lawful request, subject to applicable safeguards

Provider legal entities and notices depend on the route and region. For example, Bridge's legal overview distinguishes its regional services. An AI host, such as a platform you independently connect to an MCP server, also processes data under its own terms and settings. Review its permissions before connecting.

We may disclose relevant records to protect rights, investigate fraud or comply with a lawful demand, only on an applicable basis. If the business is transferred, necessary data may pass to a successor subject to applicable protections and notice. We do not publish private account data merely because part of a transaction is on a public blockchain.

7. International processing

Providers and their personnel may process data outside the EEA or UK. A European database location does not mean every support, email, AI or provider operation stays in Europe.

Where a restricted transfer occurs, we must use an applicable lawful mechanism, such as an adequacy decision or appropriate contractual safeguards with any necessary supplementary measures; exceptions are used only where their legal conditions are met. The mechanism depends on the recipient and transfer. Contact legal@swaps.app for information about the safeguards relevant to your data and a copy where available, with lawful redactions.

8. Your rights and complaints

Depending on applicable law, you can request access, correction, erasure, restriction, portability, information about recipients and transfers, and objection to processing based on legitimate interests. You can withdraw consent without affecting prior lawful processing. Not every right applies to every record, and exceptions must have a legal basis.

Contact legal@swaps.app. We may reasonably verify identity, using no more information than necessary. Requests are generally free; charges or refusal apply only where law permits. Under GDPR, we normally respond within one month and explain any lawful extension. If we act for a business customer, we may refer the request to it and assist.

You may complain to the Estonian Data Protection Inspectorate or your competent local authority. UK users may contact the ICO. You do not need to complain to us first. Other mandatory rights under applicable US state or other privacy laws remain available, including an authorised-agent or appeal process where required.

9. Browser choices and marketing

The Cookie Policy explains optional storage, analytics and marketing controls. Optional browser categories are off until you choose them. You can reopen preferences at /legal/cookies?preferences=1. A recognised Global Privacy Control signal disables marketing in these preferences.

Essential Service requests and server-side financial, security and diagnostic records may still occur when optional analytics is off. Client analytics and funnel-event tracking require analytics opt-in; optional campaign attribution requires marketing opt-in. A minimal tab-session referral code can be retained separately to deliver a requested benefit. They remain subject to necessity, lawful-basis and minimisation requirements. A cookie rejection does not stop information you deliberately submit for a payment or support request.

Use an unsubscribe link or contact us to stop marketing emails. Necessary account, payment, security and legal messages may continue. Browser preferences do not by themselves unsubscribe email, close a provider account or alter a separate platform's privacy settings.

10. Security

We use access controls, authentication, encrypted connections, scoped permissions, monitoring and other measures appropriate to the data and risks. No system is completely secure. We do not promise a particular certification, universal encryption configuration or absolute prevention of access.

Protect your account and signing material; share credentials only through supported delegated access. Report suspected data or credential compromise to security@swaps.app. We will address incidents and make notifications required by applicable law.

11. Children

The Service is intended for adults aged 18 or over. If you believe a child has supplied personal data, contact us so we can assess and take appropriate steps.

12. External platforms and public records

Provider checkouts, app stores, social platforms, wallet providers and AI hosts have their own notices. Their processing is not controlled merely by this notice. Public blockchain records can remain after an account is deleted; we will still consider lawful requests concerning off-chain copies and links we control.

13. Regional application

Our roles and practices are described above for users in the EEA, UK and elsewhere. Additional applicable laws can give extra rights or impose different conditions. We do not claim an exemption from a law solely because we are established in Estonia. Contact us for a regional request; mandatory rights prevail over this notice.

14. Automated controls

Automated checks can assess country eligibility, verification and account state, transaction patterns, address risk, credentials, quotas and security signals. A result can deny a route or request, restrict access, or trigger additional information or review. Risk signals can be incomplete or wrong. Human review does not necessarily precede an automated restriction.

You can ask legal@swaps.app to explain and review an adverse result and provide correcting information. Where applicable law gives safeguards for a solely automated decision with legal or similarly significant effects, we will provide the required information and rights, including human intervention and contest where required. Provider decisions are subject to the provider's own process; we can help identify the appropriate contact.

15. Changes

We update this notice when practices change and provide appropriate notice of material changes. A new notice does not by itself establish a new lawful basis. Where consent is required for a new purpose or technology, we will obtain it before the relevant processing.

Related Pages